Extension WordPress
Vulnérabilités WP-RecentComments
Cette page rassemble les failles publiées pour WP-RecentComments, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP-RecentComments
3 fiches
WP-RecentComments <= 2.2.7 – Unauthenticated Information Exposure
The WP-RecentComments plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.2.7. This can allow unauthenticated attackers to extract sensitive data including comments on posts even if the posts themselves are not…
*-2.2.7
Non indiqué
22/02/2023
WP-RecentComments <= 2.0.7 – SQL Injection
SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details…
*-2.0.7
2.1
22/09/2011
WP-RecentComments <= 2.0.6 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.
[*, 2.0.7)
2.0.7
22/09/2011
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.